Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-73571

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.
Gravedad CVSS v3.1: BAJA
Última modificación:
28/08/2026

CVE-2026-73532

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
14/08/2026

CVE-2026-73559

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in vllm/renderers/inputs/preprocess.py and OnlineRenderer.preprocess_completion() in vllm/renderers/online_renderer.py expand every element, and vllm/entrypoints/openai/completion/serving.py creates one engine generator and response slot per prompt, allowing an authenticated API client to exhaust CPU, memory, async scheduling capacity, engine request slots, and response buffering with one request. This issue is fixed in version 0.26.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-73514

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds checking as an index into an internal output-link table, resulting in an out-of-bounds write.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/08/2026

CVE-2026-73515

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/08/2026

CVE-2026-73533

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
17/08/2026

CVE-2026-55400

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CVE-2026-55400 is an integer underflow in Secure Access servers prior to<br /> version 14.57. Attackers with an authenticated session can send <br /> specially crafted traffic to a server in a non-default configuration and<br /> cause a persistent denial of service.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-55401

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CVE-2026-55401 is a null dereference vulnerability on the load-balancing<br /> sub-system of Secure Access servers prior to 14.57. Attackers can send <br /> an unauthenticated packet to a Secure Access server with load balancing <br /> enabled, which results in the internal load balancer crashing. After a <br /> successful attack, the Secure Access server is still able to accept <br /> connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-19710

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/08/2026

CVE-2026-19744

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor&amp;#39;s href attribute because the renderer&amp;#39;s sanitization step does not escape quotes
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-19487

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.<br /> <br /> The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.<br /> <br /> Example:<br /> <br /> "ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE<br /> "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed<br /> <br /> An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2026-73557

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore state can be raced by concurrent prompt_embeds parts submitted to POST /v1/chat/completions through AsyncMultiModalItemTracker.resolve_items, asyncio.gather, and the default executor, allowing an invalid sparse tensor to reach tensor.to_dense despite the CVE-2025-62164 guard when enable_prompt_embeds is enabled. This issue is fixed in version 0.26.0.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026